Meeting the challenges in log management
12/28/2007
While log management has been universally accepted as an effective tool for maintaining the security of your system or network, there are certain inherent challenges that you have to address in log management. Some of the real challenges are maintaining an effective balance among the various resources providing you logs and the growing volumes of log data. These challenges are common to almost all organizations and since the peripherals and external sources provide most of your logs, they play a major role in the preparation of your usb Policy.
You will come across several potential problems when the logs are generated initially due to their varieties and natures. Sometimes there is also the problem of breach of integrity by disclosure of the logs that could be done inadvertently. Most of the times the log analysis is prepared in a slipshod manner causing the results to be affected in the process adversely and this are a major aspect of the Security Information management.
The problems you face are that there are many log sources and you have to prioritize basing on their performance and information they provide. However the potent danger is that often the log provides incomplete information affecting adversely your enterprise security management attempts since they only store such part of the information that they consider to be vital. This inconsistency often affects the quality of the log. Last but not the least, the analyzers of the log also prepares inadequate evaluation at times which may cause acute problem for the security of your system or networking.